Trust and transparency

Privacy at GCSI

We use only the information needed to run GCSI and the features you choose to use. Optional analytics stay off unless you allow them.

Cookies and analytics

You choose whether optional analytics are used

GCSI uses necessary cookies and local storage to keep the site working, remember essential choices and support secure account features. With your permission, optional analytics help us understand which public pages are useful, where a small number of defined product tasks become difficult and where the Knowledge Hub may be missing guidance.

Optional analytics are off until you accept them. We do not enable advertising cookies or ad personalisation through this analytics setup. You can change your choice at any time from Cookie settings in the footer.

Technical details

When optional analytics are accepted, eligible public pages use Google Analytics measurement ID G-QB2ZH9G6TD. Before consent, the Google Analytics tag is not loaded by GCSI. Advertising storage, ad user data and ad personalisation remain disabled.

Private administration, sign-in and recovery, dashboard, settings, profile-management, recipe-submission, saved-recipe and recipe-management surfaces remain excluded from Google Analytics.

For a small number of defined tasks, GCSI may also keep first-party daily aggregate counts after analytics consent — for example, how many consented browsers started a recipe submission, reached each form section or successfully submitted it. This aggregate dataset stores no GCSI user ID, session identifier, email address, IP address, free-text entry, form value or full URL. It cannot reconstruct an individual person's journey. Daily aggregates are retained for up to 13 months.

When a Knowledge Hub search returns no published results, GCSI may classify the unmet search into an existing public category/tag bucket such as a controlled guidance area, or simply Unclassified search need. The phrase you typed is not sent to the search-gap analytics endpoint, stored in the search-gap dataset, hashed for later matching or shown to administrators. Search-gap rows contain only the date, Knowledge surface, controlled bucket, coarse filter state and an aggregate count, and are retained for up to 13 months.

Account and participation data

Information used to operate your account

When you create or use a GCSI account, the platform may store the account, profile, preference, contribution, moderation, notification and audit information needed for the features you use. Public profile information is controlled separately from private account records.

For account-session security, GCSI keeps a protected HMAC fingerprint of each registered session, its account session generation, a broad browser/device label, and created/last-active/revocation times. The member session registry does not store the raw PHP session identifier, IP address or raw browser user-agent string. Members can view their current session generation and sign out other sessions from Account settings.

Verification and password-recovery credentials are handled as security data and are not exposed through normal administration history. Important editorial and administrative actions may be retained in audit records for accountability and recoverability.

Email and notifications

Communication choices are separated

Essential account messages, optional activity notifications and the newsletter are separate communication channels. Newsletter consent is off by default and can be withdrawn independently of account-service messages.

Delivery and suppression records are used to operate communication safely. Administration views are designed to avoid exposing reusable verification codes, reset tokens or unnecessary recipient information.

Current scope

Public beta notice

This page describes the current platform behaviour relevant to privacy and analytics. GCSI will continue expanding the formal privacy notice as additional Restaurant Index, Academy, research and partnership workflows move from planned or pilot status into production.

For a public description of current platform roles and workflows, see How GCSI works →